Managing a vulnerability's lifecycle

Last updated: April 13, 2026

Vulnerabilities on the platform follow a lifecycle that lets you track each one from detection to resolution.

Managing this process well is what keeps risk down over time.


Vulnerability states

A vulnerability can go through different states:

  • Open: detected and pending resolution

  • In progress: currently being remediated

  • Resolved: fixed

  • Re-tested / Closed: confirmed as solved

πŸ‘‰ This gives you a clear view of where each finding stands.


Management flow

The typical cycle is:

  1. Automatic detection

  2. Finding validation

  3. Prioritization

  4. Remediation

  5. Re-test

  6. Closure

πŸ‘‰ The whole process runs as a continuous flow.

Expert validation of findings

As part of the lifecycle, every vulnerability is validated before being reported.

The Hacking Governance team plays a key role in this process:

  • Reviews critical findings

  • Filters out false positives

  • Ensures result quality

  • Confirms findings are truly exploitable

πŸ‘‰ This means every reported vulnerability comes with real context and is actionable.

πŸ’‘ Combining AI with human validation cuts down noise and sharpens testing accuracy.

Tracking vulnerabilities

The platform lets you:

  • Monitor the status of each vulnerability

  • See how it evolves over time

  • Identify backlog

πŸ‘‰ This helps your team work more efficiently.


Best practices

βœ” Keep consistent follow-up on open vulnerabilities

βœ” Prevent backlog from building up

βœ” Always confirm remediation with a re-test

βœ” Prioritize based on asset criticality

Managing the lifecycle effectively isn't just about fixing vulnerabilities β€” it's about shortening the window your systems stay exposed.